]>
Commit | Line | Data |
---|---|---|
6dd844db PB |
1 | /* |
2 | * Serving QEMU block devices via NBD | |
3 | * | |
4 | * Copyright (c) 2012 Red Hat, Inc. | |
5 | * | |
6 | * Author: Paolo Bonzini <pbonzini@redhat.com> | |
7 | * | |
8 | * This work is licensed under the terms of the GNU GPL, version 2 or | |
9 | * later. See the COPYING file in the top-level directory. | |
10 | */ | |
11 | ||
d38ea87a | 12 | #include "qemu/osdep.h" |
9c17d615 | 13 | #include "sysemu/blockdev.h" |
e140177d | 14 | #include "sysemu/block-backend.h" |
0d09e41a | 15 | #include "hw/block/block.h" |
e688df6b | 16 | #include "qapi/error.h" |
5daa6bfd | 17 | #include "qapi/qapi-commands-block-export.h" |
737e150e | 18 | #include "block/nbd.h" |
ae398278 | 19 | #include "io/channel-socket.h" |
862172f4 | 20 | #include "io/net-listener.h" |
6dd844db | 21 | |
ddffee39 | 22 | typedef struct NBDServerData { |
862172f4 | 23 | QIONetListener *listener; |
ddffee39 | 24 | QCryptoTLSCreds *tlscreds; |
00019455 | 25 | char *tlsauthz; |
1c8222b0 KW |
26 | uint32_t max_connections; |
27 | uint32_t connections; | |
ddffee39 DB |
28 | } NBDServerData; |
29 | ||
30 | static NBDServerData *nbd_server; | |
00917172 | 31 | static bool is_qemu_nbd; |
ddffee39 | 32 | |
1c8222b0 KW |
33 | static void nbd_update_server_watch(NBDServerData *s); |
34 | ||
00917172 KW |
35 | void nbd_server_is_qemu_nbd(bool value) |
36 | { | |
37 | is_qemu_nbd = value; | |
38 | } | |
39 | ||
5b1cb497 KW |
40 | bool nbd_server_is_running(void) |
41 | { | |
42 | return nbd_server || is_qemu_nbd; | |
43 | } | |
44 | ||
0c9390d9 EB |
45 | static void nbd_blockdev_client_closed(NBDClient *client, bool ignored) |
46 | { | |
47 | nbd_client_put(client); | |
1c8222b0 KW |
48 | assert(nbd_server->connections > 0); |
49 | nbd_server->connections--; | |
50 | nbd_update_server_watch(nbd_server); | |
0c9390d9 | 51 | } |
6dd844db | 52 | |
862172f4 DB |
53 | static void nbd_accept(QIONetListener *listener, QIOChannelSocket *cioc, |
54 | gpointer opaque) | |
6dd844db | 55 | { |
1c8222b0 KW |
56 | nbd_server->connections++; |
57 | nbd_update_server_watch(nbd_server); | |
58 | ||
0d73f725 | 59 | qio_channel_set_name(QIO_CHANNEL(cioc), "nbd-server"); |
00019455 | 60 | nbd_client_new(cioc, nbd_server->tlscreds, nbd_server->tlsauthz, |
0c9390d9 | 61 | nbd_blockdev_client_closed); |
6dd844db PB |
62 | } |
63 | ||
1c8222b0 KW |
64 | static void nbd_update_server_watch(NBDServerData *s) |
65 | { | |
66 | if (!s->max_connections || s->connections < s->max_connections) { | |
67 | qio_net_listener_set_client_func(s->listener, nbd_accept, NULL, NULL); | |
68 | } else { | |
69 | qio_net_listener_set_client_func(s->listener, NULL, NULL, NULL); | |
70 | } | |
71 | } | |
ddffee39 DB |
72 | |
73 | static void nbd_server_free(NBDServerData *server) | |
6dd844db | 74 | { |
ddffee39 | 75 | if (!server) { |
6dd844db PB |
76 | return; |
77 | } | |
78 | ||
862172f4 DB |
79 | qio_net_listener_disconnect(server->listener); |
80 | object_unref(OBJECT(server->listener)); | |
ddffee39 DB |
81 | if (server->tlscreds) { |
82 | object_unref(OBJECT(server->tlscreds)); | |
83 | } | |
00019455 | 84 | g_free(server->tlsauthz); |
ddffee39 DB |
85 | |
86 | g_free(server); | |
87 | } | |
88 | ||
89 | static QCryptoTLSCreds *nbd_get_tls_creds(const char *id, Error **errp) | |
90 | { | |
91 | Object *obj; | |
92 | QCryptoTLSCreds *creds; | |
93 | ||
94 | obj = object_resolve_path_component( | |
95 | object_get_objects_root(), id); | |
96 | if (!obj) { | |
97 | error_setg(errp, "No TLS credentials with id '%s'", | |
98 | id); | |
99 | return NULL; | |
100 | } | |
101 | creds = (QCryptoTLSCreds *) | |
102 | object_dynamic_cast(obj, TYPE_QCRYPTO_TLS_CREDS); | |
103 | if (!creds) { | |
104 | error_setg(errp, "Object with id '%s' is not TLS credentials", | |
105 | id); | |
106 | return NULL; | |
107 | } | |
108 | ||
109 | if (creds->endpoint != QCRYPTO_TLS_CREDS_ENDPOINT_SERVER) { | |
110 | error_setg(errp, | |
111 | "Expecting TLS credentials with a server endpoint"); | |
112 | return NULL; | |
113 | } | |
114 | object_ref(obj); | |
115 | return creds; | |
116 | } | |
117 | ||
118 | ||
bd269ebc | 119 | void nbd_server_start(SocketAddress *addr, const char *tls_creds, |
1c8222b0 KW |
120 | const char *tls_authz, uint32_t max_connections, |
121 | Error **errp) | |
ddffee39 DB |
122 | { |
123 | if (nbd_server) { | |
124 | error_setg(errp, "NBD server already running"); | |
ae398278 | 125 | return; |
6dd844db | 126 | } |
ae398278 | 127 | |
ddffee39 | 128 | nbd_server = g_new0(NBDServerData, 1); |
1c8222b0 | 129 | nbd_server->max_connections = max_connections; |
862172f4 DB |
130 | nbd_server->listener = qio_net_listener_new(); |
131 | ||
132 | qio_net_listener_set_name(nbd_server->listener, | |
133 | "nbd-listener"); | |
134 | ||
fc8135c6 | 135 | if (qio_net_listener_open_sync(nbd_server->listener, addr, 1, errp) < 0) { |
ddffee39 DB |
136 | goto error; |
137 | } | |
138 | ||
bd269ebc | 139 | if (tls_creds) { |
ddffee39 DB |
140 | nbd_server->tlscreds = nbd_get_tls_creds(tls_creds, errp); |
141 | if (!nbd_server->tlscreds) { | |
142 | goto error; | |
143 | } | |
144 | ||
bd269ebc MA |
145 | /* TODO SOCKET_ADDRESS_TYPE_FD where fd has AF_INET or AF_INET6 */ |
146 | if (addr->type != SOCKET_ADDRESS_TYPE_INET) { | |
ddffee39 DB |
147 | error_setg(errp, "TLS is only supported with IPv4/IPv6"); |
148 | goto error; | |
149 | } | |
150 | } | |
151 | ||
00019455 DB |
152 | nbd_server->tlsauthz = g_strdup(tls_authz); |
153 | ||
1c8222b0 | 154 | nbd_update_server_watch(nbd_server); |
ddffee39 DB |
155 | |
156 | return; | |
157 | ||
158 | error: | |
159 | nbd_server_free(nbd_server); | |
160 | nbd_server = NULL; | |
6dd844db PB |
161 | } |
162 | ||
eed8b691 KW |
163 | void nbd_server_start_options(NbdServerOptions *arg, Error **errp) |
164 | { | |
1c8222b0 KW |
165 | nbd_server_start(arg->addr, arg->tls_creds, arg->tls_authz, |
166 | arg->max_connections, errp); | |
eed8b691 KW |
167 | } |
168 | ||
bd269ebc MA |
169 | void qmp_nbd_server_start(SocketAddressLegacy *addr, |
170 | bool has_tls_creds, const char *tls_creds, | |
00019455 | 171 | bool has_tls_authz, const char *tls_authz, |
1c8222b0 | 172 | bool has_max_connections, uint32_t max_connections, |
bd269ebc MA |
173 | Error **errp) |
174 | { | |
175 | SocketAddress *addr_flat = socket_address_flatten(addr); | |
176 | ||
1c8222b0 | 177 | nbd_server_start(addr_flat, tls_creds, tls_authz, max_connections, errp); |
bd269ebc MA |
178 | qapi_free_SocketAddress(addr_flat); |
179 | } | |
180 | ||
b6076afc | 181 | void qmp_nbd_server_add(NbdServerAddOptions *arg, Error **errp) |
56ee8626 | 182 | { |
9b562c64 KW |
183 | BlockExport *export; |
184 | BlockDriverState *bs; | |
185 | BlockBackend *on_eject_blk; | |
b6076afc | 186 | BlockExportOptions *export_opts; |
9b562c64 KW |
187 | |
188 | bs = bdrv_lookup_bs(arg->device, arg->device, errp); | |
189 | if (!bs) { | |
190 | return; | |
191 | } | |
192 | ||
b6076afc KW |
193 | /* |
194 | * block-export-add would default to the node-name, but we may have to use | |
195 | * the device name as a default here for compatibility. | |
196 | */ | |
197 | if (!arg->has_name) { | |
198 | arg->name = arg->device; | |
199 | } | |
200 | ||
201 | export_opts = g_new(BlockExportOptions, 1); | |
202 | *export_opts = (BlockExportOptions) { | |
203 | .type = BLOCK_EXPORT_TYPE_NBD, | |
d53be9ce | 204 | .id = g_strdup(arg->name), |
b6076afc | 205 | .node_name = g_strdup(bdrv_get_node_name(bs)), |
30dbc81d KW |
206 | .has_writable = arg->has_writable, |
207 | .writable = arg->writable, | |
b6076afc KW |
208 | .u.nbd = { |
209 | .has_name = true, | |
210 | .name = g_strdup(arg->name), | |
211 | .has_description = arg->has_description, | |
212 | .description = g_strdup(arg->description), | |
b6076afc KW |
213 | .has_bitmap = arg->has_bitmap, |
214 | .bitmap = g_strdup(arg->bitmap), | |
215 | }, | |
56ee8626 | 216 | }; |
9b562c64 KW |
217 | |
218 | /* | |
219 | * nbd-server-add doesn't complain when a read-only device should be | |
220 | * exported as writable, but simply downgrades it. This is an error with | |
221 | * block-export-add. | |
222 | */ | |
223 | if (bdrv_is_read_only(bs)) { | |
30dbc81d KW |
224 | export_opts->has_writable = true; |
225 | export_opts->writable = false; | |
9b562c64 KW |
226 | } |
227 | ||
b6076afc | 228 | export = blk_exp_add(export_opts, errp); |
9b562c64 | 229 | if (!export) { |
b6076afc | 230 | goto fail; |
9b562c64 KW |
231 | } |
232 | ||
233 | /* | |
234 | * nbd-server-add removes the export when the named BlockBackend used for | |
235 | * @device goes away. | |
236 | */ | |
237 | on_eject_blk = blk_by_name(arg->device); | |
238 | if (on_eject_blk) { | |
239 | nbd_export_set_on_eject_blk(export, on_eject_blk); | |
240 | } | |
b6076afc KW |
241 | |
242 | fail: | |
243 | qapi_free_BlockExportOptions(export_opts); | |
6dd844db PB |
244 | } |
245 | ||
a3b0dc75 | 246 | void qmp_nbd_server_remove(const char *name, |
3c3bc462 | 247 | bool has_mode, BlockExportRemoveMode mode, |
a3b0dc75 VSO |
248 | Error **errp) |
249 | { | |
3c3bc462 | 250 | BlockExport *exp; |
a3b0dc75 | 251 | |
3c3bc462 KW |
252 | exp = blk_exp_find(name); |
253 | if (exp && exp->drv->type != BLOCK_EXPORT_TYPE_NBD) { | |
254 | error_setg(errp, "Block export '%s' is not an NBD export", name); | |
a3b0dc75 VSO |
255 | return; |
256 | } | |
257 | ||
3c3bc462 | 258 | qmp_block_export_del(name, has_mode, mode, errp); |
a3b0dc75 VSO |
259 | } |
260 | ||
6dd844db PB |
261 | void qmp_nbd_server_stop(Error **errp) |
262 | { | |
7801c3a7 EB |
263 | if (!nbd_server) { |
264 | error_setg(errp, "NBD server not running"); | |
265 | return; | |
266 | } | |
267 | ||
bc4ee65b | 268 | blk_exp_close_all_type(BLOCK_EXPORT_TYPE_NBD); |
6dd844db | 269 | |
ddffee39 DB |
270 | nbd_server_free(nbd_server); |
271 | nbd_server = NULL; | |
6dd844db | 272 | } |